Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Understanding Section 7 Of The UK Bribery Act

The UK Bribery Act 2010 created one of the most demanding corporate anti-corruption offences in the world. Section 7 makes a commercial organisation criminally liable when an associated person bribes another person to obtain or retain business, or to secure a business advantage for the organisation. The offence focuses on the organisation’s failure to prevent bribery rather than on proof that senior management knew about the payment.

This approach has changed how companies assess third-party risk, design compliance programmes, and document business controls. A business can face prosecution even where the alleged bribe was paid by an intermediary, consultant, distributor, subsidiary, or joint-venture representative acting without the knowledge of the board.

Section 7 is a strict liability offence, but an organisation has a statutory defence if it can demonstrate that it had adequate procedures designed to prevent associated persons from undertaking bribery. In practice, this makes prevention, risk assessment, training, monitoring, and evidence of implementation central to UK anti-bribery compliance.

What The Corporate Offence Covers

Section 7 applies when a person associated with a commercial organisation bribes another person intending to obtain or retain business, or to obtain a business advantage for that organisation. The underlying conduct will usually involve an offence under section 1 of the Act, concerning bribing another person, or section 6, concerning bribery of a foreign public official.

The organisation does not have to authorise, approve, or know about the bribe. There is no requirement to prove that a director or senior manager acted dishonestly. The central question is whether the associated person was performing services for, or on behalf of, the organisation and whether the organisation failed to maintain adequate preventive procedures.

The offence can apply to companies incorporated in the United Kingdom and to certain partnerships. It can also apply to an overseas business that carries on a business, or part of a business, in the UK. The Act does not define this territorial connection with a simple numerical test, so businesses should examine their UK operations, subsidiaries, contracts, personnel, and commercial activities carefully.

Associated Persons And Territorial Reach

An associated person is someone who performs services for or on behalf of the organisation. Employees, agents, and subsidiaries may fall within this category, but the label used in a contract is not decisive. A person’s actual role, relationship, and function will matter more than whether the organisation calls them a contractor, adviser, broker, or distributor.

The wider the individual’s ability to represent the organisation or influence a transaction, the greater the potential Section 7 exposure. A sales intermediary paid by commission, a customs facilitator, a local partner seeking permits, and a consultant managing government relationships may all require enhanced scrutiny. A supplier that merely provides goods may present a different risk profile from an agent negotiating contracts, although the facts of each relationship remain important.

The conduct may occur outside the United Kingdom, and the bribe may involve a foreign public official, private-sector employee, or another recipient. A UK connection through the organisation or its business activities can therefore create significant international exposure. Multinational groups should avoid assuming that local customs, foreign subsidiaries, or overseas payment practices place the activity outside the Act.

Parent companies should also distinguish between ownership and operational control. A subsidiary is not automatically an associated person of its parent for every activity, but the relationship may create risk where the subsidiary acts on behalf of the parent or where the parent directs, benefits from, or relies on its conduct. Contractual arrangements, reporting lines, shared personnel, and transaction purpose all deserve review.

The Adequate Procedures Defence

The adequate procedures defence is available when the organisation proves that it had adequate procedures designed to prevent persons associated with it from bribing others. The burden rests with the organisation. It is not enough to produce a policy document after an incident; the procedures should be proportionate to the organisation’s risk and actively implemented before the misconduct occurred.

The UK government’s guidance is built around six principles: proportionate procedures, top-level commitment, risk assessment, due diligence, communication including training, and monitoring and review. These principles are intended to be flexible. A small domestic business does not need the same compliance infrastructure as a global engineering group operating through agents in high-risk jurisdictions, but both should be able to explain why their controls are reasonable.

A credible defence depends on evidence. Useful records may include risk assessments, approval workflows, due diligence files, training attendance, gifts and hospitality registers, payment reviews, audit findings, investigation reports, and evidence that concerns were escalated. Controls should address how the organisation actually operates, including urgent transactions, politically exposed persons, government tenders, charitable contributions, and unusual commission arrangements.

The term “adequate” does not mean perfect. A business may still experience an isolated act of bribery despite having a well-designed programme. The key issue is whether its procedures were appropriately designed, properly resourced, understood by relevant personnel, and adapted when risks changed.

Comparing Common Section 7 Risk Areas

Risk area Typical warning signs Practical controls
Third-party agents High commissions, vague services, requests for cash or offshore payment Background checks, written contracts, beneficial ownership review, invoice testing, audit rights
Government-facing work Licensing, customs, inspections, public procurement, permits Enhanced due diligence, approval by compliance or legal teams, payment controls, transaction monitoring
Gifts and hospitality Lavish events, travel for officials, personal benefits, timing before a decision Clear thresholds, pre-approval, registers, recipient checks, documented business purpose
Facilitation payments Small unofficial payments described as routine or necessary Prohibition, escalation channels, emergency reporting, accurate books and records
Acquisitions and joint ventures Limited access to records, inherited intermediaries, inconsistent policies Pre-acquisition review, contractual protections, integration plan, post-deal testing
Charitable and political contributions Donations linked to permits, contracts, officials, or intermediaries Independent review, recipient verification, written rationale, transparent payment trail

The table illustrates why a single generic policy will rarely be sufficient. Risk-based controls should reflect the organisation’s markets, sectors, transaction structures, third parties, and interaction with public officials. A business operating in a low-risk domestic market may need fewer layers of approval than a company using brokers to win infrastructure contracts abroad.

Businesses should also maintain accurate financial records. Concealing a payment, misdescribing a commission, or using vague expense categories can create additional accounting and fraud concerns, while weak records make it harder to demonstrate that preventive measures were working. Internal audit and finance teams therefore have an important role in Section 7 compliance.

Facilitation Payments, Hospitality And Corporate Conduct

The UK Bribery Act does not create an exception for facilitation payments. Small payments made to speed up routine governmental action can therefore create criminal risk, even where they are common in a particular country or described locally as a normal administrative practice. Policies should state this clearly and provide a safe process for employees who face threats, coercion, or immediate personal danger.

Gifts and hospitality are not automatically unlawful. Reasonable and proportionate hospitality connected to a legitimate business purpose may be acceptable. Risk increases when the benefit is lavish, concealed, provided to influence a decision, directed at a close relative, or offered shortly before a tender, inspection, licence, or regulatory determination.

The same reasoning applies to charitable donations, sponsorships, internships, travel, and political contributions. A payment can create bribery risk even if it is recorded under a socially beneficial label. Companies should assess the recipient, purpose, timing, decision-making context, and ultimate beneficiary before approving the expenditure.

Communication is especially important in markets where employees may face pressure to make unofficial payments. Staff need practical examples, confidential reporting channels, guidance on refusing requests, and protection against retaliation. A policy that employees cannot follow safely or understand in operational conditions will provide limited protection.

Building A Defensible Compliance Programme

An effective programme begins with a documented risk assessment rather than a collection of disconnected policies. Management should identify where the organisation obtains business, who represents it, which public bodies or officials it contacts, how payments are made, and where local law or commercial practice may increase exposure.

The following controls can help translate Section 7 expectations into daily business processes:

  • Classify third parties by risk and conduct proportionate due diligence before appointment.
  • Use written contracts that define services, prohibit bribery, regulate subcontracting, and preserve audit rights.
  • Require approval for commissions, success fees, gifts, hospitality, donations, sponsorships, and unusual expenses.
  • Deliver role-specific training to employees and associated persons, with attendance and completion records.
  • Monitor payments and relationships, investigate red flags, and review controls after incidents or market changes.

Due diligence should continue after onboarding. A clean initial screening result does not remove the need to review ownership changes, adverse media, unusual invoices, unexplained delays, requests for new bank accounts, or sudden increases in commission. Higher-risk relationships may require periodic certification, site visits, transaction testing, and direct contact with the third party’s management.

Senior leadership should demonstrate commitment through decisions and resources, not statements alone. If commercial teams can bypass compliance controls to meet targets, employees will receive a clear signal about the organisation’s real priorities. Incentive structures, disciplinary practices, reporting lines, and escalation decisions should all reinforce the company’s anti-bribery standards.

Investigations, Enforcement And Business Impact

The Serious Fraud Office can investigate potential Section 7 violations, often in coordination with other domestic or international authorities. Prosecution may follow a self-report, whistleblower allegation, audit finding, law enforcement referral, or evidence uncovered during another investigation. Cooperation, preservation of documents, legal privilege considerations, and disciplined internal fact-finding can materially affect how a company responds.

A company convicted under Section 7 may receive an unlimited fine. The commercial effects can extend beyond the penalty, including legal costs, management disruption, loss of customers, damaged reputation, regulatory scrutiny, and possible consequences for participation in public procurement. Individuals involved in the underlying bribery may face separate offences and personal criminal liability.

Deferred prosecution agreements can be available to corporate bodies in appropriate cases. They generally require conditions such as payment of a financial penalty, cooperation, disclosure, compensation, or improvement of compliance systems. A DPA is not an automatic alternative to prosecution, and its suitability depends on the facts, the organisation’s conduct, and the prosecutor’s assessment.

When an allegation arises, the organisation should preserve relevant communications and financial records, prevent document destruction, assess whether payments should be suspended, and protect potential witnesses from interference. It should also consider whether third parties, subsidiaries, lenders, insurers, customers, or regulators need to be notified. Reliable response planning is part of prevention because it limits the damage caused by a control failure.

Companies developing or reviewing their anti-corruption framework should use authoritative legal materials alongside operational guidance and country-specific risk information. General resources cannot replace advice tailored to particular facts, and users should review the site disclaimer when relying on online compliance information.

Section 7 compliance is strongest when it becomes part of procurement, sales, finance, human resources, internal audit, and senior management decisions. Organisations should map their highest-risk relationships, test whether controls work in practice, and keep evidence showing that weaknesses are addressed promptly. Taking those steps now can reduce exposure to bribery, strengthen business relationships, and place the company in a better position if regulators later examine its preventive procedures.

copyright © Global Advice Network